Go seems to have taken a look at the carnage of decades of dependency hell and decided "if we make no effort to provide a system then people will be forced to produce sane stable APIs".
I've picked the short straw of trying to reproducibly build and package Go based projects for internal projects. The combination of go get and the Go ecosystem's cultural lack of versioning and stability are giving me a deep dislike of the language.
First you have to play git-bisect on the dependencies (after you've hunted them down because of repo renames) in order to find the most recent one it builds against (and who knows if that was the one written against!) Then you have to futz around to add in either some custom or third party vendoring script, and then you have to rinse and repeat for second order dependencies.
For example, take the author's own first linked project. Following the build instructions:
~ $ mkdir ~/syslog-gollector
~ $ cd ~/syslog-gollector
~/syslog-gollector $ export GOPATH=$PWD
~/syslog-gollector $ go get github.com/otoolep/syslog-gollector
package github.com/otoolep/syslog-gollector
imports code.google.com/p/log4go
imports github.com/otoolep/sarama
imports code.google.com/p/snappy-go/snappy: unable to detect version control system for code.google.com/ path
~/syslog-gollector $ go install github.com/otoolep/syslog-gollector
src/github.com/otoolep/sarama/snappy.go:5:2: cannot find package "code.google.com/p/snappy-go/snappy" in any of:
/usr/lib/golang/src/code.google.com/p/snappy-go/snappy (from $GOROOT)
/home/ldite/syslog-gollector/src/code.google.com/p/snappy-go/snappy (from $GOPATH)
Well, I'm shocked.